Opencats is a modestly represented but prominently deployed open-source applicant-tracking system, offering a single product that attracts attention disproportionate to its code volume due to its foothold in human-resources workflows and direct exposure to internet-facing web interfaces. Vulnerabilities affecting this product skew toward serious outcomes, with an elevated share reaching critical severity, and frequently acquire public exploit tooling. The exposure recurs consistently through a cluster of input-handling and data-processing weakness classes including cross-site scripting, SQL injection, cross-site request forgery, untrusted deserialization, and XML external entity reference flaws that are endemic to web applications built without contemporary input-validation and output-encoding discipline. Defenders should treat Opencats deployments as high-priority targets for patching and access control, given the sensitivity of recruitment and personnel data at stake; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opencats over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27760HIGH OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injec | Apr 28, 2026 | 8.1 | 60 | NO | YES |
CVE-2019-13358HIGH lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker must upload a file in the docx or | Jul 5, 2019 | 7.5 | 48 | NO | YES |
CVE-2021-41560CRITICAL OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php. | Dec 15, 2021 | 9.8 | 36 | NO | NO |
CVE-2021-25294CRITICAL OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occurs because lib/DataGrid.php calls unserialize for the param | Jan 18, 2021 | 9.8 | 36 | NO | NO |
CVE-2026-49489HIGH OpenCATS through 0.9.7.4 contains a sql injection vulnerability in the sortDirection parameter of the DataGrid component that allows authenticated users to extract database content | May 31, 2026 | 8.5 | 35 | NO | NO |
CVE-2021-47936CRITICAL OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by uploading malicious PHP files disguised as resu | May 10, 2026 | 9.8 | 35 | NO | NO |
CVE-2026-49490HIGH OpenCATS from version 0.9.1a contains an SQL injection vulnerability in DataGrid filter handling that allows authenticated attackers to inject SQL through crafted filters targeting | May 31, 2026 | 8.1 | 34 | NO | NO |
CVE-2022-43019CRITICAL OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality. | Oct 19, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-43016MEDIUM OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component. | Oct 19, 2022 | 6.1 | 31 | NO | YES |
CVE-2022-43015MEDIUM OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter. | Oct 19, 2022 | 6.1 | 31 | NO | YES |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opencats.
Media articles that mention a CVE ID that affects a product developed by Opencats — matched by CVE ID, not by vendor name.